Class/Module Index [+]

Quicksearch

Rex::ElfScan::Scanner::PopPopRetScanner

Public Instance Methods

config(param) click to toggle source
# File lib/rex/elfscan/scanner.rb, line 137
def config(param)
        pops = _build_byte_list(0x58, (0 .. 7).to_a - [4]) # we don't want pop esp's...
        self.regex = Regexp.new("[#{pops}][#{pops}](\xc3|\xc2..)", nil, 'n')
end
scan_segment(program_header, param={}) click to toggle source
# File lib/rex/elfscan/scanner.rb, line 142
def scan_segment(program_header, param={})
        offset = program_header.p_offset

        hits = []

        while offset < program_header.p_offset + program_header.p_filesz &&
        (offset = elf.index(regex, offset)) != nil

                rva     = elf.offset_to_rva(offset)
                message = ''

                pops = elf.read(offset, 2)
                reg1 = Rex::Arch::X86.reg_name32(pops[0,1].unpack('C*')[0] & 0x7)
                reg2 = Rex::Arch::X86.reg_name32(pops[1,1].unpack('C*')[0] & 0x7)

                message = "pop #{reg1}; pop #{reg2}; "

                retsize = _ret_size(offset+2)
                message += _parse_ret(elf.read(offset+2, retsize))

                offset += 2 + retsize

                hits << [ rva, message ]
        end

        return hits
end

[Validate]

Generated with the Darkfish Rdoc Generator 2.